Three protocols hit in rapid‑fire exploits, losing over $35 million

23-Jul-2026 Crypto Economy

TL;DR

  • An exploit targeting AFX Trade, a perpetuals exchange on Arbitrum, drained $24.15 million from its USDC custody bridge.
  • The protocol offered the attacker the option to keep 30% of the stolen funds as a “white hat bounty” if the remaining 70% is returned.
  • The Verus-Ethereum bridge suffered a second exploit in two months, resulting in losses of $7.54 million through the same vulnerability that was exploited in May.

An exploit on multiple fronts shook the DeFi ecosystem, with two attacks that caused losses exceeding $31 million in a matter of hours. AFX Trade, a decentralized exchange for perpetual contracts on Arbitrum that settles in USDC, was drained and lost $24.15 million after an attacker compromised the custody bridge operated by the protocol itself. Blockchain security firm Blockaid confirmed the incident. AFX noted that the exact attack vector remains under investigation.

The on-chain trail documented by PeckShield reveals that the attacker converted the stolen USDC into 12,468 ETH, assets that were concentrated in a single wallet. AFX suspended bridge operations immediately and clarified that the vulnerability was “isolated to the custody bridge operated by AFX” and could not affect the protocol’s trading infrastructure or the Arbitrum network. Steven Goldfeder, co-founder of Arbitrum, was quick to publicly clarify that the network’s native bridge “was not hacked or exploited in any way.”

Exploits as Negotiating Currency

Hours after the incident, Ken C, AFX’s head of growth, published a direct offer to the attacker: return 70% of the funds and keep the remaining 30% as a “white hat” bounty. The tactic is not new in the crypto industry; Drift Protocol on Solana attempted a similar negotiation after losing $285 million in an exploit in April.

Exploits defi cross chain bridges peckshield

The second attack of the day targeted the Verus-Ethereum bridge, which lost approximately $7.54 million through the same class of vulnerability exploited in May. According to Blockaid, the attacker abused the bridge’s import path to generate unbacked payments on the Ethereum side, draining ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD before converting everything into ETH. CertiK estimated losses at $7.53 million and confirmed that the funds were deposited into Tornado Cash.

What deepens the gravity of the case is that this second attack used the same contract, the same entry path, and the same class of vulnerability as the May exploit, though with a different attacker operating from a new wallet. The previous incident had caused losses of $11.6 million, though the attacker returned 4,052 ETH after retaining 25% as a bounty.

Finally, less than an hour later, PeckShield reported that attackers drained 8.59 million B2 tokens from BSquaredNetwork on BNB Chain, resulting in losses of approximately $3.86 million. The hackers quickly swapped the tokens for more than 5,000 WBNB, then converted them into 1,128 ETH before bridging the funds out via NEAR Intents

Both attacks add to the list of a devastating year for decentralized finance, which has accumulated more than $840 million in losses from hacks during 2026.

Also read: SHIB Attempts a Comeback, but Buyers Still Face a Major Test
WHAT'S YOUR OPINION?
Related News